Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
25,049 results · page 104 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2016-1102 | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs… | EXPLOIT ✓HIGH 7.5EPSS 37.2% | 11 May 2016 |
| CVE-2016-1101 | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs… | EXPLOIT ✓HIGH 7.5EPSS 35.3% | 11 May 2016 |
| CVE-2016-1096 | Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs… | EXPLOIT ✓HIGH 7.5EPSS 37.2% | 11 May 2016 |
| CVE-2016-1077 | Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of… | EXPLOIT ✓CRITICAL 9.8EPSS 15.5% | 11 May 2016 |
| CVE-2016-4117 | Adobe Flash Player Arbitrary Code Execution Vulnerability | KEVEXPLOIT ✓CRITICAL 9.8EPSS 94.4% | 11 May 2016 |
| CVE-2016-0189 | Microsoft Internet Explorer Memory Corruption Vulnerability | KEVEXPLOITHIGH 7.5EPSS 94.1% | 11 May 2016 |
| CVE-2016-0185 | Microsoft Windows Media Center Remote Code Execution Vulnerability | KEVEXPLOIT ✓HIGH 7.8EPSS 69.8% | 11 May 2016 |
| CVE-2016-0173 | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted… | EXPLOIT ✓HIGH 7.8EPSS 3.53% | 11 May 2016 |
| CVE-2016-0171 | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted… | EXPLOIT ✓HIGH 7.8EPSS 4.30% | 11 May 2016 |
| CVE-2016-0170 | GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document,… | EXPLOIT ✓HIGH 8.8EPSS 35.0% | 11 May 2016 |
| CVE-2016-0169 | GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted… | EXPLOIT ✓MEDIUM 6.5EPSS 27.8% | 11 May 2016 |
| CVE-2016-0168 | GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted… | EXPLOIT ✓MEDIUM 6.5EPSS 27.8% | 11 May 2016 |
| CVE-2015-0569 | Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and… | EXPLOITHIGH 7.8EPSS 6.47% | 9 May 2016 |
| CVE-2016-4535 | Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted packed executable. | EXPLOIT ✓HIGH 7.5EPSS 8.22% | 5 May 2016 |
| CVE-2016-4534 | The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on Windows allows local administrators to bypass intended self-protection rules and unlock the console window by closing registry handles. | EXPLOITLOW 3.0EPSS 2.73% | 5 May 2016 |
| CVE-2016-3718 | ImageMagick Server-Side Request Forgery (SSRF) Vulnerability | KEVEXPLOITMEDIUM 5.5EPSS 76.7% | 5 May 2016 |
| CVE-2016-3717 | The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. | EXPLOITMEDIUM 5.5EPSS 28.0% | 5 May 2016 |
| CVE-2016-3716 | The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image. | EXPLOITLOW 3.3EPSS 18.9% | 5 May 2016 |
| CVE-2016-3715 | ImageMagick Arbitrary File Deletion Vulnerability | KEVEXPLOITMEDIUM 5.5EPSS 75.3% | 5 May 2016 |
| CVE-2016-3714 | ImageMagick Improper Input Validation Vulnerability | KEVEXPLOIT ×2 ✓HIGH 8.4EPSS 97.5% | 5 May 2016 |
| CVE-2016-2107 | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an… | EXPLOIT ✓MEDIUM 5.9EPSS 89.1% | 5 May 2016 |
| CVE-2016-3140 | The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB… | EXPLOITMEDIUM 4.6EPSS 1.55% | 2 May 2016 |
| CVE-2016-3136 | The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two… | EXPLOITMEDIUM 4.6EPSS 1.59% | 2 May 2016 |
| CVE-2016-2854 | The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. | EXPLOITHIGH 7.8EPSS 0.95% | 2 May 2016 |
| CVE-2016-2853 | The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program. | EXPLOITHIGH 7.8EPSS 0.91% | 2 May 2016 |
| CVE-2016-2188 | The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device… | EXPLOITMEDIUM 4.6EPSS 1.49% | 2 May 2016 |
| CVE-2016-1576 | The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted… | EXPLOITHIGH 7.8EPSS 1.13% | 2 May 2016 |
| CVE-2016-1575 | The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. | EXPLOITHIGH 7.8EPSS 0.92% | 2 May 2016 |
| CVE-2016-3672 | The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and… | EXPLOITHIGH 7.8EPSS 1.16% | 27 April 2016 |
| CVE-2016-3139 | The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device… | EXPLOITMEDIUM 4.6EPSS 1.55% | 27 April 2016 |
| CVE-2016-3135 | Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE… | EXPLOIT ✓HIGH 7.8EPSS 1.00% | 27 April 2016 |
| CVE-2016-3134 | The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. | EXPLOIT ✓HIGH 8.4EPSS 0.97% | 27 April 2016 |
| CVE-2016-2782 | The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a… | EXPLOITMEDIUM 4.6EPSS 1.65% | 27 April 2016 |
| CVE-2016-2384 | Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an… | EXPLOITMEDIUM 4.6EPSS 3.08% | 27 April 2016 |
| CVE-2016-2184 | The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via… | EXPLOITMEDIUM 4.6EPSS 1.65% | 27 April 2016 |
| CVE-2015-7515 | The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints. | EXPLOITMEDIUM 4.6EPSS 1.80% | 27 April 2016 |
| CVE-2016-3081 | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions. | EXPLOIT ✓HIGH 8.1EPSS 82.9% | 26 April 2016 |
| CVE-2016-3074 | Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow. | EXPLOITCRITICAL 9.8EPSS 37.0% | 26 April 2016 |
| CVE-2016-2203 | The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges. | EXPLOITHIGH 7.8EPSS 7.77% | 22 April 2016 |
| CVE-2016-1596 | Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4)… | EXPLOITMEDIUM 5.4EPSS 3.26% | 22 April 2016 |
| CVE-2016-1595 | LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the… | EXPLOITMEDIUM 6.5EPSS 6.23% | 22 April 2016 |
| CVE-2016-1594 | Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action. | EXPLOITMEDIUM 6.5EPSS 6.62% | 22 April 2016 |
| CVE-2016-1593 | Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. | EXPLOIT ×2HIGH 7.2EPSS 60.2% | 22 April 2016 |
| CVE-2016-2004 | HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. | EXPLOIT ×2 ✓CRITICAL 9.8EPSS 93.1% | 21 April 2016 |
| CVE-2016-0891 | Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the authentication of administrators. | EXPLOIT ✓HIGH 8.8EPSS 3.91% | 20 April 2016 |
| CVE-2016-3943 | Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by… | EXPLOITHIGH 7.8EPSS 1.18% | 18 April 2016 |
| CVE-2015-7378 | Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe. | EXPLOITHIGH 7.8EPSS 0.85% | 18 April 2016 |
| CVE-2016-2417 | media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process… | EXPLOIT ✓CRITICAL 9.8EPSS 4.11% | 18 April 2016 |
| CVE-2016-0846 | libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider the heap size, which allows attackers to gain privileges via a crafted… | EXPLOIT ✓HIGH 8.4EPSS 0.98% | 18 April 2016 |
| CVE-2016-2056 | xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c. | EXPLOIT ✓HIGH 8.8EPSS 53.1% | 13 April 2016 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.